PoC Index

CVE-2017-7478

HIGH 7.5EPSS 13.9%

OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.

CVSS v3.0
7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS
13.89% chance of exploitation in the next 30 days, 96th percentile
Published
2017-05-15
Updated
2024-08-05

ExploitDB entries (1)

References

Related